Linux Information
 
ÃÑ °Ô½Ã¹° 125°Ç, ÃÖ±Ù 0 °Ç
   
SNORT ¼³Ä¡ ¹× ¿î¿µ
±Û¾´ÀÌ : ½Å¿µÃ¶ ³¯Â¥ : 2013-01-18 (±Ý) 12:52 Á¶È¸ : 27253

SNORT ¼³Ä¡ ¹× ¿î¿µ 

¼³Ä¡È¯°æÀº ´ÙÀ½°ú °°´Ù.

Glibc 2.1.3
libpcap 0.6.2
SNORT 1.8.2


SNORT¼³Ä¡

º»ÀÎÀº ÇÁ·Î±×·¥ ÀÚü¿¡ ´ëÇÑ ¼³¸íÀ» ¸¹ÀÌ ÇÏÁö´Â ¾Ê´Â´Ù.
ÀÚ½ÅÀÌ ¿øÇÒ¶§ ÇØ¾ß ÁýÁß·ÂÀ̳ª ÀÌÇØ·Â¿¡ Á¤Á¡¿¡ À̸£´Â °ÍÀÌ´Ù. - °©Àڱ⠶׵ýÁö ..
SNORT´Â IDS(Instrusion Detection System)ÀÌ´Ù.
Áï, ±âÁ¸ ¹æÈ­º®µîÀÌ ¿ÜºÎÀÇ Ä§ÀÔÀ» ¸·´Âµ¥ ÁßÁ¡À» µÎ¾ú´Ù¸é(iptables, tcp wrapper...),
ÀÌ ³ðÀº ħÀÔÇÏ·Á´Â °ÍÀ» ŽÁöÇϴµ¥ ÁßÁ¡À» µÎ¾ú´Ù. ÆÐŶ³»ÀÇ Æ¯Á¤ ºÎºÐÀÌ(ħÀÓÈçÀûÀ̶ó°í ÆÇ´ÜµÇ´Â)
¹ß°ßµÇ¸é À̸¦ ŽÁöÇÒ ¼ö ÀÖ´Ù. ÀÌ·± ƯÁ¤ ºÎºÐÀº °è¼Ó °»½ÅµÇ¾î¾ß ÇϹǷΠ·ê¼ÂÀ̶ó´Â º°µµÀÇ
ÆÄÀÏ·Î °è¼Ó °»½ÅµÇ¾î Á¦°øµÇ°í ÀÖ´Ù.


libpcap ¼³Ä¡
snort´Â libpcap¶óÀ̺귯¸®¸¦ »ç¿ëÇϹǷΠ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é ¼³Ä¡ÇØ ÁØ´Ù.

[root@ns /down]$ wget http://www.tcpdump.org/daily/libpcap-current.tar.gz
[root@ns /down]# tar xvzf libpcap-current.tar.gz -C /usr/local/src
[root@ns /down]# cd /usr/local/src/libpcap-2001.11.03
[root@ns libpcap-2001.11.03]# ./configure
[root@ns libpcap-2001.11.03]# make


snort ¼³Ä¡
SNORT´Â www.snort.org¿¡¼­ ¹èÆ÷ÇÑ´Ù.

[root@ns /down]# wget http://www.snort.org/releases/snort-1.8.2.tar.gz
[root@ns /down]# tar xvzf snort-1.8.2.tar.gz -C /usr/local/src
[root@ns /down]# cd /usr/local/src/snort-1.8.2/
[root@ns snort-1.8.2]# ./configure
[root@ns snort-1.8.2]# make
[root@ns snort-1.8.2]# make install


»ç¿ë
¹èÆ÷tar¿¡ SnortUsersManual.pdf¶ó´Â ¸Å´º¾óÀÌ µé¾î ÀÖÀ¸´Ï º¸¸é µÇ°Ú´Ù.
±×³É ½©ÇÁ·ÒÇÁÆ®¿¡¼­ snort¶ó°í¸¸ ÀÔ·ÂÇÏ¿© ½ÇÇàÇØº¸ÀÚ.

[root@ns snort-1.8.2]# snort
Log directory = /var/log/snort

Initializing Network Interface eth0
using config file ./snort.conf
Initializing Preprocessors!
Initializing Plug-ins!
Initializating Output Plugins!
Parsing Rules file ./snort.conf

+++++++++++++++++++++++++++++++++++++++++++++++++++
Initializing rule chains...
No arguments to frag2 directive, setting defaults to:
    Fragment timeout: 60 seconds
    Fragment memory cap: 4194304 bytes
Stream4 config:
    Stateful inspection: ACTIVE
    Session statistics: INACTIVE
    Session timeout: 30 seconds
    Session memory cap: 8388608 bytes
    State alerts: INACTIVE
    Scan alerts: ACTIVE
    Log Flushed Streams: INACTIVE
No arguments to stream4_reassemble, setting defaults:
    Reassemble client: ACTIVE
    Reassemble server: INACTIVE
    Reassemble ports: 21 23 25 53 80 143 110 111 513
    Reassembly alerts: ACTIVE
Back Orifice detection brute force: DISABLED
Using LOCAL time
882 Snort rules read...
882 Option Chains linked into 92 Chain Headers
0 Dynamic rules
+++++++++++++++++++++++++++++++++++++++++++++++++++

Rule application order: ->activation->dynamic->alert->pass->log

        --== Initializing Snort ==--

Initializing Network Interface eth0
Decoding Ethernet on interface eth0

        --== Initialization Complete ==--

-*> Snort! <*-
Version 1.8.2 (Build 86)
By Martin Roesch (roesch@sourcefire.com, www.snort.org)

Foreground·Î ½ÇÇàµÇ¾úÀ¸¹Ç·Î Á¾·áÇÏ·Á¸é Ctrl+C¸¦ ´©¸¥´Ù.

===============================================================================
Snort analyzed 1222 out of 1222 packets, dropping 0(0.000%) packets

Breakdown by protocol:                Action Stats:
    TCP: 484        (39.607%)        ALERTS: 33       
    UDP: 109        (8.920%)          LOGGED: 33       
  ICMP: 0          (0.000%)          PASSED: 0       
    ARP: 375        (30.687%)
  IPv6: 0          (0.000%)
    IPX: 0          (0.000%)
  OTHER: 253        (20.704%)
DISCARD: 0          (0.000%)
===============================================================================
Fragmentation Stats:
Fragmented IP Packets: 0          (0.000%)
    Fragment Trackers: 0       
  Rebuilt IP Packets: 0       
  Frag elements used: 0       
Discarded(incomplete): 0       
  Discarded(timeout): 0       
  Frag2 memory faults: 0       
===============================================================================
TCP Stream Reassembly Stats:
        TCP Packets Used: 484        (39.607%)
        Stream Trackers: 41       
          Stream flushes: 1       
          Segments used: 1       
  Stream4 Memory Faults: 0       
===============================================================================
Snort received signal 2, exiting
[root@ns snort-1.8.2]#

À§¿¡¼­ º¸µíÀÌ ±âº»ÀûÀ¸·Î 882ÀÇ ·ê(rule)ÀÌ Á¦°øµÈ´Ù.
ÀÌ´Â Ãß°¡ÀûÀ¸·Î Á¤ÀÇµÉ ¼ö ÀÖÀ¸¹Ç·Î ·ê¼ÂÀÇ °³³äÀº Áß¿äÇÏ´Ù.


ruleset ¼³Ä¡
snortrules.tar.gz¿¡´Â snort¼³Á¤ÆÄÀÏÀÎ snort.confÆÄÀÏÀÌ Á¸ÀçÇÑ´Ù.

[root@ns /down]# wget http://www.snort.org/downloads/snortrules.tar.gz
[root@ns /down]# tar xvzf snortrules.tar.gz -C /usr/local/bin
[root@ns /down]# cd /usr/local/bin/rules

snort.conf¿¡¼­ ¼³Á¤
´ÙÀ½°ªµéÀ» ÀÚ½ÅÀÇ È¯°æ¿¡ ¸Â°Ô ÁöÁ¤ÇÏ°í ³ª¸ÓÁö´Â µðÆúÆ®·Î »ç¿ëÇÑ´Ù.
¹ÙÀÌ·¯½º(´Ô´Ù,..)·Î ÀÎÇØ ISS¿¡ ´ëÇÑ ·Î±×°¡ ¸¹À¸¹Ç·Î µð½ºÅ© Àý¾àÂ÷¿ø¿¡¼­ ¾Æ¿¹ »©¹ö·È´Ù.
os°¡ ¸®´ª½ºÀ̹ǷΠÀÌ¿¡ ´ëÇÑ ÇÇÇØ´Â ¾øÀ»°ÍÀÌ´Ù.

var HOME_NET 211.41.23.0/24
preprocessor portscan-ignorehosts: $DNS_SERVERS
#include web-iis.rules

½ÇÇà
[root@ns src]# snort -D -b -A fast -c /usr/local/bin/rules/snort.conf
-D: µ¥¸ó¸ðµå
-b: textº¯È­Á¦°Å
-c: ¼³Á¤ÆÄÀÏ ÁöÁ¤

Å×½ºÆ®
È£½ºÆ® B¿¡¼­ È£½ºÆ® A·Î Æ÷Æ®½ºÄµÀ» ÇØº»´Ù.


[È£½ºÆ®B]
[root@A /down]# nmap -O -sS 211.41.23.236

[È£½ºÆ®A]
/var/log/snort/alert
11/04-04:27:16.607990  [**] [1:618:1] INFO - Possible Squid Scan [**] [Classification: Attempted Information
 Leak] [Priority: 2] {TCP} 211.41.23.252:37372 -> 211.41.23.236:3128
11/04-04:27:18.580974  [**] [100:1:1] spp_portscan: PORTSCAN DETECTED to port 25 from 211.41.23.252
 (STEALTH) [**]
11/04-04:27:18.580209  [**] [111:12:1] spp_stream4: NMAP FINGERPRINT (stateful) detection [**] {TCP}
211.41.23.252:37382 -> 211.41.23.236:25
11/04-04:27:18.580257  [**] [1:628:1] SCAN nmap TCP [**] [Classification: Attempted Information Leak]
[Priority: 2] {TCP} 211.41.23.252:37384 -> 211.41.23.236:1
11/04-04:27:18.580282  [**] [111:10:1] spp_stream4: STEALTH ACTIVITY (nmap XMAS scan) detection [**]
{TCP} 211.41.23.252:37385 -> 211.41.23.236:1
11/04-04:27:21.380211  [**] [111:12:1] spp_stream4: NMAP FINGERPRINT (stateful) detection [**] {TCP}
211.41.23.252:37382 -> 211.41.23.236:25
11/04-04:27:21.380260  [**] [1:628:1] SCAN nmap TCP [**] [Classification: Attempted Information Leak]
[Priority: 2] {TCP} 211.41.23.252:37384 -> 211.41.23.236:1
11/04-04:27:21.380284  [**] [111:10:1] spp_stream4: STEALTH ACTIVITY (nmap XMAS scan) detection [**]
{TCP} 211.41.23.252:37385 -> 211.41.23.236:1
11/04-04:27:24.181210  [**] [100:2:1] spp_portscan: portscan status from 211.41.23.252: 3 connections
 across 1 hosts: TCP(3), UDP(0) STEALTH [**]
11/04-04:27:24.180302  [**] [111:12:1] spp_stream4: NMAP FINGERPRINT (stateful) detection [**] {TCP}
 211.41.23.252:37382 -> 211.41.23.236:25
11/04-04:27:24.180351  [**] [1:628:1] SCAN nmap TCP [**] [Classification: Attempted Information Leak]
 [Priority: 2] {TCP} 211.41.23.252:37384 -> 211.41.23.236:1
11/04-04:27:24.180376  [**] [111:10:1] spp_stream4: STEALTH ACTIVITY (nmap XMAS scan) detection
[**] {TCP} 211.41.23.252:37385 -> 211.41.23.236:1
[root@ns snort]# cat portscan.log
Nov  4 04:27:24 211.41.23.252:37380 -> 211.41.23.236:25 NULL ********
Nov  4 04:27:21 211.41.23.252:37381 -> 211.41.23.236:25 NMAPID **U*P*SF
Nov  4 04:27:21 211.41.23.252:37385 -> 211.41.23.236:1 XMAS **U*P**F


[SNORT SNARF]
snort·Î±×ÆÄÀÏÀ» ºÐ¼®ÇØ À¥ÆäÀÌÁö¿¡¼­ º¼ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù.
MRTG°°ÀÌ CRONÀ¸·Î µ¹·Á º»´Ù. ´Ü, mrtg°¡ º¸Åë 5ºÐÁÖ±â·Î µ¹¸®Áö¸¸, ÀÌ ³ðÀº 1ÀÏÁÖ±â·Î µ¹¸®´Â °ÍÀÌ ÁÁ°Ú´Ù.
ÀÌ ÅøÀº snort»çÀÌÆ®¿¡ ¸µÅ©µÇ¾î ÀÖ¾î ±¦ÂúÀº(?) ³ðÀ̶ó°í »ý°¢Çß´Ù.
ÇÏÁö¸¸... ÀÚ¿ø»ç¿ëÀÌ ³Ê¹« ¸¹´Ù. ¼­¹ö»ç¾çÀÌ ¿Ø¸¸Å­ ¹ÞÃÄÁÖÁö ¾ÊÀ¸¸é Àý´ë µ¹¸®Áö ¸»¶ó.
¿¹) alert·Î±×Å©±â°¡ 11MÁ¤µµÀÏ ¶§ ½ÇÇàÇßÀ¸³ª, ³¡³¯ »ý°¢À» ¾ÈÇß´Ù.
topÀ¸·Î ÆÄ¾ÇÇÑ CPU, ¸Þ¸ð¸®»ç¿ë·®Àº °¢°¢ 90%ÀÌ»ó, 140MÀÌ»óÀ¸·Î ¼­¹ö´Ù¿îÀÇ À§±â¸¦ ´À²¼´Ù.
Áï½Ã, ½ÇÇàÀ» Ãë¼ÒÇϰí, alert¸¦ Áö¿ì°í portscan.log(Å©±â°¡ 944byte¹Û¿¡ µÇÁö ¾Ê´Â´Ù)¸¸À¸·Î ´Ù½Ã ½ÇÇàÇØºÃÀ¸³ª
5ÃÊÁ¤µµ °É·È´ø °Í °°´Ù. ¹°·Ð ÀÌ ¶§µµ ¸®¼Ò½º»ç¿ë·®Àº ½Ã°£¿¡ ºñ·ÊÇØ ±âÇϱ޼öÀûÀ¸·Î ¿Ã¶ó°¬´Ù.
¼º´ÉÀÌ ³Ê¹« ½Ç¸Á½º·¯¿ö, ¾²Áö ¾Ê±â·Î °áÁ¤Çß´Ù.
snort·Î±×ºÐ¼®ÅøÀ» ¸î°³ ã°í ÀÖ´Ù. ÀÌÁß °¡Àå ±¦ÂúÀº ³ðÀ» ãÀ»¸é À̱ÛÀ» ¾÷µ¥ÀÌÆ®ÇÒ °ÍÀÌ´Ù.

snortSnarf¼³Ä¡°úÁ¤
[root@ns SnortSnarf-010821.1]# cd include/
[root@ns include]# cp -R * /usr/lib/perl5/site_perl/5.005/

[root@ns SnortSnarf-010821.1]# cd cgi/
[root@ns cgi]# cp * /usr/local/apache/cgi-bin/

[root@ns SnortSnarf-010821.1]# cp snortsnarf.pl /usr/local/bin

snortsnarf.pl \
-rulesdir /usr/local/bin/rules \
-rulesfile /usr/local/bin/rules/snort.conf \
-d /webhosting/admin/snort /var/log/snort/alert /var/log/snort/portscan.log


ÂüÁ¶:
http://www.certcc.or.kr/tools/Snort.html
http://www.snort.org
http://www.silicondefense.com/software/snortsnarf/index.htm

½Å¿µÃ¶ ´ÔÀÇ Linux ÃÖ½Å±Û [´õº¸±â]


   

 

naver.com daum.net nate.com google.co.kr youtube.com


Copyright ¨Ï www.pronice.com. All rights reserved.